Skip to content

Require explicit trace_prompt opt-in for prompt payload logging - #1891

Open
augustd wants to merge 1 commit into
anthropics:mainfrom
augustd:codex/require-explicit-prompt-tracing
Open

augustd wants to merge 1 commit into
anthropics:mainfrom
augustd:codex/require-explicit-prompt-tracing

Conversation

@augustd

@augustd augustd commented Oct 9, 2026

Copy link
Copy Markdown

Tag mode currently prints the complete generated prompt and extracted user request before invoking Claude, even with show_full_output: false. Inline review comments include attached diff context, so a credential in the commented-on code can be copied into the Actions log without appearing in the comment body.

Add trace_prompt, defaulting to false. Only the exact value true enables these two payload logs. Prompt files continue to be written for Claude in both cases; show_full_output and GitHub Actions debug mode do not implicitly enable tracing. The input description and documentation explain the exposure risk when opting in.

with:
  trace_prompt: "true"

Validation: all 972 tests pass, including regression cases for omitted, empty, false, uppercase, numeric, and true tracing inputs. The regression uses synthetic credentials in review diff context and confirms prompt/request files remain intact. TypeScript, formatting of changed files, and action input/default/runtime mapping checks pass.

Co-authored-by: Codex GPT-6 <codex@openai.com>
@augustd
augustd marked this pull request as ready for review October 9, 2026 00:29

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant